CVE-2026-14841

The King Addons for Elementor WordPress plugin before 51.1.76 does not escape a user-supplied grid setting before reflecting it into an HTML attribute in an unauthenticated AJAX response, allowing attackers to execute arbitrary JavaScript in the browser of a visitor who is tricked into loading a crafted page.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-02 06:16

Updated : 2026-08-26 16:31


NVD link : CVE-2026-14841

Mitre link : CVE-2026-14841

CVE.ORG link : CVE-2026-14841


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')